Discovered by ESET security researcher Lukas Stefanko, the code of this Android spyware is present in a public repository titled 'OwnMe' on GitHub. The malware contains a MainActivity.class which launches OwnMe.class service. When activated, it shows a popup reading "Service Started" to the Android user. After the service is initiated, a startExploit() function starts, and the spyware establishes an internet connection to the server.The OwnMe malware includes a
function that can upload local WhatsApp database to a command-and-control centre, as well as the username and android_id from the start-up process. The spyware also uses getHistory() function to grab titles, times, URLs and visits from user bookmarks.
This also targets contacts, phone numbers and call logs if the WhatsApp application on affected device is permitted to access call history. The code that the spyware contains can also compromise gallery, camera, and can also read battery levels and CPU usage.
No comments:
Post a Comment